Business Continuity Management Planning Methodology
|
|
|
- Kristian Crawford
- 10 years ago
- Views:
Transcription
1 , pp Business Continuity Management Planning Methodology Dr. Goh Moh Heng, Ph.D., BCCLA, BCCE, CMCE, CCCE, DRCE President, BCM Institute Managing Director, GMH Continuity Architects Abstract This paper explains the concept of business continuity management (BCM) with the specific focus on the BCM planning process and methodology. Before entering into the maintenance phase of any BCM program, the Organization BCM Coordinator needs to ensure that the project phases of the BCM planning methodology are succinctly implemented to meet the organization s BCM objectives. This paper is an update of an earlier paper written in 1996 incorporating the author s subsequent experiences and implementation while he is working in the financial regulatory environment. This BCM methodology is aligned with the BCM standard ISO The intent in the following dialog is to explain the BCM planning process briefly. Keywords: Business Continuity planning methodology, Project Management, Risk Analysis and Review, Business Impact Analysis, Business Continuity Strategy, Plan Development, Testing and Exercising, Program Management, ISO Introduction Business Continuity Management [1] is a holistic management process that identifies potential threats to an organization and the impacts to business operations those threats, if realized, might cause, and which provides a framework for building organizational resilience with the capability for an effective response that safeguards the interests of its key stakeholders, reputation, brand and value-creating activities. Businesses are subject to disruptions of varying severity. An incident, emergency or event, if not managed properly, can escalate to become a disaster or crisis. Besides creating an unplanned disruption that can tarnish an organization's image, in the extreme case, this incident if not properly managed can result in significant physical or environmental damage. It may cause significant injuries to employees or even death. For example, a fire outbreak if not brought under control quickly can result in grave consequences. Organizations should, therefore, be prepared for an incident before it occurs to minimize its impact should it happen. 2. BCM Planning Methodology The BCM planning methodology (Figure 1), like any other planning process, provides a framework for requirements, effort, and deliverables, each phase leading into the next in an endlessly repeating cycle. In real life, many of the steps or phases can be conducted concurrently. While these steps provide visual clues as to the amount of execution time to take, they are used as a reference and do not represent an absolute percentage of the time. ISSN: IJDRBC Copyright c2015 SERSC
2 Figure 1. BCM Planning Methodology This BCM planning methodology [2] started with the author being tasked to develop and implement a business continuity planning methodology for a large international UKbased bank. The planning methodology has been subjected to the rigor of both successful global implementation of BC plans for the bank's 52 franchisees. This methodology has been subjected to the highest level of academic scrutiny as part of a Doctor of Philosophy dissertation [3]. In researching for this thesis, more than 200 types of proprietary BCM processes and methodologies had been evaluated. For more than a decade since the completion of the thesis, the BCM planning methodology had undergone an evolutionary process of continuous improvement, to form the framework for BCM Institute s training curriculum. 3. Definition As defined in BCMPedia [4], the BCM planning methodology is the planning process for the implementation of any BC plan. The phases are as follows: Project Management. Risk Analysis and Review. Business Impact Analysis. Business Continuity Strategy. Plan Development. Testing and Exercising. Program Management. 4. Project Management The first step in implementing the BCM planning methodology in any organization is to set up the needed Executive Management structure, to support the BCM planning process [5]. Here is where we confirm the inclusion of the business units and the business functions in the scope and the roles and responsibilities of each party participating in the project. This inclusion is to ensure the efficient completion of task assignments and time goals, which will have to be set at a later stage of the project. The BC project planning team will need to: Obtain the commitment of Heads of Business Units and their staff members, and involve them in the BCM planning process. 10 Copyright c 2015 SERSC
3 Identify and mobilize the business units resources. Begin the information gathering process What does the Project Management Entail? The entire project management process involves the following steps. Establish the need for BCM planning. Research the work in the areas of BCM. Develop a BCM planning framework. Define the scope, objectives, and assumptions. Manage the BCM planning process. Establish a BCM project planning committee and team. Develop an action plan and schedule. Establish a budget. Obtain commitment and approval. Manage deadlines and milestones. Build and maintain teamwork. The detailed breakdown of the steps can be found in the first book [1] of the BCM Book Series. 5. Risk Analysis and Review The Risk Analysis and Review phase is the detailed analysis of risks, vulnerabilities (exposures) and probabilities [6] and is a component of risk assessment. The Risk Analysis & Review phase along with the following Business Impact Analysis phase is key fundamental elements of an organization s BCM Program. The Risk Analysis & Review phase is not the end game but rather a starting point in the BCM planning process. It is an industry-recognized approach to helping an organization determine which disruptive events are they vulnerable. How to address these vulnerabilities and where they can maximize the value of the dollars they spend on their unique BCM efforts. The purpose of a Risk Analysis & Review phase is the mitigation or minimizing of the risks and threats to the organization. The major steps and considerations during the Risk Analysis & Review [7] process include: Assess the risk. Assess the control options. Assess the cost and the effectiveness of risk controls. Establish the Key Disaster Scenario. Report to the Executive Management. Implement, maintain and monitor the effectiveness of controls. Copyright c 2015 SERSC 11
4 6. Business Impact Analysis The Business Impact Analysis (BIA) phase refers to the process of identifying an organization s Critical Business Functions and analyzing the potential disruptive impact to the business [7]. The Business Impact Analysis phase is to: Assess the impact of a disruption to any functional area or business operations within the organization. Determine the extent to which primarily functional and operational dependencies exist within the organization. Establish the restoration priorities and sequence of the critical IT applications and essential business functions What does the Business Impact Analysis Process Entail? The entire Business Impact Analysis process involves the following steps: Gather Information. Design the Business Impact Analysis Questionnaires. Gather initial information about business functions, support systems and IT applications through the use of Business Impact Analysis Questionnaires. Verify and Analyze Information. Validate the content of the submitted Business Impact Analysis Questionnaires with Business Unit BCM Coordinators. Conduct face-to-face interviews with Business Unit BCM Coordinators to verify the accuracy of the information presented. Analyze information to determine priorities for recovery of business operations, systems, and IT applications. Establish a Recovery Time Objective for each Critical Business Functions, which is the time taken from disruption until recovery of services. Document and Present Findings. Prepare the executive summary and the Business Impact Analysis report. Include recovery priorities supported by graphs, charts, and other working aids. Present a set of findings to the Executive Management in written and oral reports. Update the Executive Management on the subsequent steps in the BCM planning process. 7. Business Continuity Strategy The development of the BC Strategy is the process to determine and select operating strategy to maintain or continue the critical business functions or product and services during a disaster [8] What does the Development of BC Strategy Entail? The entire BC Strategy [8] process involves the following stages: 12 Copyright c 2015 SERSC
5 Initiate the BC Strategy Project and Design. Understand the development process for BC Strategy. Evaluate current status and arrangement. Prepare a project plan. Develop and Consolidate BC Strategy. Design working document for completing the BC Strategy information. Conduct the BC Strategy workshop. Design and develop BC Strategy by the business units BCM coordinators and their heads. Review and consolidate submissions from business units by the organizational BCM project team. Finalize Strategy and Obtain Acceptance for the strategy. Validate design of the individual and corporate BC strategy. Finalize the corporate-level BC Strategy. Obtain approval from Executive Management. 8. Plan Development In the plan development phase [9], you will need to identify all the procedures and resources necessary to initiate the BC documentation. The BC plan will contain all the pertinent details from the Business Impact Analysis and BC Strategy Phases. The completed plan is an important document, as all staff in the business units will rely on it for instruction and guidance in the event of a disaster. It is, therefore, necessary for the BC plan to be well structured and developed in a series of logical steps. As the team proceeds, please keep in mind that the BC procedures should be entirely self-contained and simple to use. The BC plan will be based on all the procedures and priorities agreed upon by the executive management so that the need to refer or make decisions in a disaster will be kept to an absolute minimum What does the Plan Development Phase Entail? The entire Plan Development [9] process involves the following stages. Determine the Organization of the Plan Document. Design and develop BC plan template. Determine and finalize the recovery organization. Conduct a Plan Writing Workshop to Guide BC Plan Writers. Facilitate the completion of the plan template by individual business units BCM Coordinators. Finalize the production of the BC Plan. Validate the content of BC plans by business units' BCM Coordinators and Heads of Business Units for their completeness and coverage. Copyright c 2015 SERSC 13
6 Sign-off by heads of respective business units. 9. Testing and Exercising Testing & Exercising is needed to ensure the business continuity (BC) plan works [10]. The BC plan must be tested to prove its validity. Testing is intended to find errors and omissions in the BC plan procedures. These corrected omissions or errors can be reported to all concerned parties and subsequently. The process of simulating a recovery based on the procedures within the BC document also prepares the relevant staff to function at the alternate site and verifies the adequacy of the alternative site. Ultimately, the Testing & Exercising phase ensures the integrity of the complete business continuity plan, with appropriately documented procedures to handle all likely situations What does Testing and Exercising Entail? The entire Testing and Exercising [10] process involves the three main stages: Designing the Test Program. Executing the Test. Assessing and correcting the results of the tests and exercises. In stage 1, which is the Designing the Test Program, the components of this stages includes. The First Component is the development of a corporate-wide test and exercise program. The appointed person responsible for BC plan should develop this program, and it will be done in consultation with executive management. The program should identify all the tests and exercises that are required. The Second Component is for Specific Tests defined within the test program; the following questions should be asked? What is the aim of the test? What does each test try to prove? What is the scope of the test? To what extent do they wish to test? Who will be involved? Which components should they test? What is the method that will be used for conducting the test? How will the test be performed? The Third Component is an Evaluation mechanism that must be developed to assess whether the tests were successful. Specific, measurable criteria must be established to decide whether each test achieves a pass or fail result. In stage 2, this entails running the Test. Here is where the actual test is executed based on the planned scope of testing. In the last stage, the test results are assessed against the pre-determined criteria. An evaluation of the outcome of causes of any deviations, either through errors or omissions, and corrections are made to the BC plan. As part of the continuous improvement process, there is always a need to fine-tune the test plan where relevant, for future testing. The team should perform tests and exercises on all aspects of a BC plan, such as Information Technology (IT) system switch-over, telephone notification call trees, and evacuation methods. These tests should be discussed with relevant staff to determine the most appropriate model and test schedule. Testing helps identify vulnerabilities and changes in the organizational environment and allows the renewal of the BC plan accordingly. For the tests to be valid, it must challenge the recovery needs of the organization. Each member of the BC team is strongly recommended to be involved in some form of testing twice every year. A test policy to revise the readiness of their plans should be developed and published. 14 Copyright c 2015 SERSC
7 A mandatory corporate policy to perform "at least once per year" testing should be published and endorsed by Executive Management. This regular distribution of the resultant revised BC plans to all recovery personnel. 10. Program Management Once the BCM planning project completes, the next challenge is to keep the BCM program effort alive. It is essential to emphasize continuously that, in the event of a disaster, BCM is the key to ensuring the safety of all people in the organization as well as the survivability of the organization. The objective of the Program Management phase is to establish an on-going system to ensure the validity of critical business functions, BC Strategy and documented recovery procedures [11]. The ultimate goal is the recoverability of the business processes in the organization What does BCM Program Management Entail? Some of the activities that have to be completed under the Program Management [11] phase, and they ensure that the: BC Plan is consistent with the most current business operational setup. BC Plan is available, accessible and distributed to the recovery team. Maintain BC Plan to an acceptable standard, efficiency, and effectiveness. Planning efforts enable the prompt and correct response of the staff in a disaster. BC Plan is consistent with international standards. In summary, it is important to maintain the BC Plan regularly and updated and kept actually. The primary considerations in this process include the: Maintenance process. Incorporation of the training & awareness phase to institute it as part of the organizational training program. Development of advanced level testing and exercising. Constant review and audit of the BC plan and its preparedness. Embedding of the BCM mindset and culture into the organization. 11. Conclusion This planning methodology covers the Plan, Do, Check and Act components of the Plan-Do-Check-Act or PDCA cycle as mandated by any typical ISO management system. The intent is to ensure that BCM process develop a workable BC plan. The BCM planning methodology continues to be the cornerstone for all BCM planning activities. This methodology includes a requirement for Pandemic Flu planning [12], IT disaster recovery planning [13] and crisis management [14]. References [1] ISO, Editor, ISO22301:2012 Societal Security Business Continuity Management Systems Requirements, (1st ed., p. 24), International Organization for Standardization, Switzerland, (2012). [2] M. H. Goh, Developing a suitable business continuity planning methodology, Information Management & Computer Security, vol. 4, no. 2, (1996), pp [3] M. H. Goh, Editor, Business Continuity Planning for Banks in Asia: A Case Study in Standard Chartered Bank, University of South Australia, (1999). Copyright c 2015 SERSC 15
8 [4] M. H. Goh, Editor, CMpedia: A Wiki Glossary for Business Continuity Management, Crisis Management and Disaster Recovery (4th ed., p. 200), BCM Institute, Singapore. (2013). [5] M. H. Goh, Editor, Managing Your Business Continuity Planning Project (2nd ed., p. 166), GMH Pte Ltd, Singapore. (2008). [6] M. H. Goh, Editor, Analyzing & Reviewing the Risks for Business Continuity Planning, (2nd ed., p. 148), GMH Pte Ltd, Singapore, (2008). [7] M. H. Goh, Editor, Conducting Your Impact Analysis for Business Continuity Planning, (2nd ed., p. 130), GMH Pte Ltd, Singapore, (2008). [8] M. H. Goh, Editor, Developing Recovery Strategy for Your Business Continuity Plan, (1st ed., p. 104), GMH Pte Ltd, Singapore, (2005). [9] M. H. Goh, Editor, Implementing Your Business Continuity Plan, (2nd ed., p. 104). GMH Pte Ltd, Singapore, (2010). [10] M. H. Goh, Editor, Testing and Exercising Your Business Continuity Plan, (2nd ed., p. 160), GMH Pte Ltd, Singapore, (2006). [11] M. H. Goh, Editor, Managing & Sustaining Your Business Continuity Management Program, (1st ed., p. 190), GMH Pte Ltd, Singapore, (2007). [12] M. H. Goh, Editor, A Manager s Guide to to Implement Your Infectious Disease Business Continuity Plan, (1st ed., p. 128), GMH Pte Ltd, Singapore, (2015). [13] M. H. Goh, Editor, A Manager s Guide to Managing and Implementing Your IT Disaster Recovery Plan, (1st ed., p. 208), GMH Pte Ltd, Singapore, (2010). [14] M. H. Goh, Editor, A Manager s Guide to Implement Your Crisis Management Plan, (1st ed., p. 208), GMH Pte Ltd, Singapore, (2015). Author Dr. Goh Moh Heng, Dr Goh is the President of BCM Institute and the Managing Director of GMH Continuity Architects a specialized BCM Consulting firm. His primary areas of expertise include Business Continuity Management (BCM), Disaster Recovery Planning (DRP), ISO22301 BCM Audit and Crisis Management. Since 2011, Moh Heng has assisted more than 20 organizations, particularly those operating in the Asia Pacific and Middle-East Region in their successful implementation of their Business Continuity Management System (BCMS) and achieving their BS 25999/ SS 540 / ISO organization certification. Prior to establishing BCM Institute and GMH BCM Consulting, Dr Goh held senior positions with a number of large organizations. During his career with the Government of Singapore Investment Corporation (GIC), he was responsible for all aspects of its BCM and crisis management. At Standard Chartered Bank Plc, he saw to the global implementation of its BCM and planning. He also managed the BCM practice at PricewaterhouseCoopers. Currently, Dr Goh is an expert panel member of the Asia-Pacific Economic Cooperation (APEC) Network on Improving SME Disaster Resilience (since 2011) and JICA-ASEAN study to enhance resiliency of industrial areas against natural disasters (since 2012). In May 2012, Dr Goh Moh Heng became the first Asian in the 16th year of tradition, to be awarded the "Business Continuity Lifetime Achievement Award" in London, United Kingdom by the Continuity, Insurance and Risk (CIR) Magazine. In January 2013, Dr Goh Moh Heng received the National BCM Awards 2013 from Singapore Business Federation and SPRING Singapore. 16 Copyright c 2015 SERSC
Business Continuity Planning (BCP) 101
2011/EPWG/WKSP/004 Intro 1 Business Continuity Planning (BCP) 101 Submitted by: Business Continuity Management Institute Workshop on Private Sector Emergency Preparedness Sendai, Japan 1-3 August 2011
Introduction to Business Continuity Planning
Introduction to Business Continuity Planning Business Continuity and Disaster Resilience Forum May 10, 2012 Rizal Ballroom A, Makati Shangri-la Manila, Philippines Dr Goh Moh Heng President BCM Institute
Crisis Communication and Management: Lessons from Some Recent Crises/ Disasters
Crisis Communication and Management: Lessons from Some Recent Crises/ Disasters Dr Goh Moh Heng President 1 BCM Institute We are a global convergence of thought leadership in Business Continuity, Disaster
By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd
BS 25999 Business Continuity Management By. Mr. Chomnaphas Tangsook Business Director BSI Group ( Thailand) Co., Ltd 1 Contents slide BSI British Standards 2006 BS 25999(Business Continuity) 2002 BS 15000
Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD.
Business Continuity Management & Disaster Recovery Planning Presented by: Shankar Gawade VP IT INFRASTRUCTURE ENAM SECURITIES PVT. LTD. 1 What is Business Continuity Management? Is a holistic management
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program subsidiaries) 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis
Business Continuity Management Framework 2014 2017
Business Continuity Management Framework 2014 2017 Blackpool Council Business Continuity Framework V3.0 Page 1 of 13 CONTENTS 1.0 Forward 03 2.0 Administration 04 3.0 Policy 05 4.0 Business Continuity
Business Continuity Policy
Business Continuity Policy 1 NHS England INFORMATION READER BOX Directorate Medical Commissioning Operations Patients and Information Nursing Trans. & Corp. Ops. Commissioning Strategy Finance Publications
ISO 22301 BUSINESS CONTINUITY MANAGEMENT SYStEMS (BCMS) EXPERT IMPLEMENTER
ISO 22301 BUSINESS CONTINUITY MANAGEMENT SYStEMS (BCMS) EXPERT IMPLEMENTER COMPETENCY LEVEL COMPETENCY WHICH LEVEL SHOULD I BE STARTING MY BUSINESS CONTINUITY TRAINING? KNOW DO BCM-230 BCM-330 I am new
Temple university. Auditing a business continuity management BCM. November, 2015
Temple university Auditing a business continuity management BCM November, 2015 Auditing BCM Agenda 1. Introduction 2. Definitions 3. Standards 4. BCM key elements IT Governance class - IT audit program
www.td.com.au Business Continuity - IT Disaster Recovery Discussion Paper - - Commercial in Confidence Version V2.0R Wednesday, 5 September 2012
Business Continuity - IT Disaster Recovery Discussion Paper - - Version V2.0R Wednesday, 5 September 2012 Commercial in Confidence Melbourne Sydney 79-81 Coppin St Level 2 Richmond VIC 3121 414 Kent St
Company Management System. Business Continuity in SIA
Company Management System Business Continuity in SIA Document code: Classification: Company Project/Service Year Document No. Version Public INDEX 1. INTRODUCTION... 3 2. SIA S BUSINESS CONTINUITY MANAGEMENT
BT Conferencing Business Continuity Management. Planning to stay in business
BT Conferencing Business Continuity Management Planning to stay in business Planning for the unexpected In today s connected world, businesses are increasingly dependent on their communications and networked
Business Continuity Management Policy
Business Continuity Management Policy Business Continuity Policy Version 1.0 1 Version control Version Date Changes Author 0.1 April 13 1 st draft PH 0.2 June 13 Amendments in line with guidance PH 0.3
Business Continuity Policy
Page 1 of 16 Business Continuity Policy Issue Date: Aug 2013 Document Number: 00241 Prepared by: Business Management and Continuity Senior Manager Next Review Date: April 2014 Page 2 of 16 NHS England
Proposal for Business Continuity Plan and Management Review 6 August 2008
Proposal for Business Continuity Plan and Management Review 6 August 2008 2008/8/6 Contents About Newton IT / Quality of our services. BCM & BS25999 Overview 2. BCM Development in line with BS25999 3.
Business Continuity Policy
Business Continuity Policy Page 1 of 15 Business Continuity Policy First published: Amendment record Version Date Reviewer Comment 1.0 07/01/2014 Debbie Campbell 2.0 11/07/14 Vicky Ryan Updated to include
www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014
www.pwc.com Business Resiliency Business Continuity Management - January 14, 2014 Agenda Key Definitions Risks Business Continuity Management Program BCM Capability Assessment Process BCM Value Proposition
The PNC Financial Services Group, Inc. Business Continuity Program
The PNC Financial Services Group, Inc. Business Continuity Program 1 Content Overview A. Introduction Page 3 B. Governance Model Page 4 C. Program Components Page 4 Business Impact Analysis (BIA) Page
BUSINESS CONTINUITY MANAGEMENT SINGAPORE SS540 BCM STANDARDS. LSA Consultants Pte Ltd
BUSINESS CONTINUITY MANAGEMENT SINGAPORE SS540 BCM STANDARDS LSA Consultants Pte Ltd BCM SINGAPORE LSA Consultants Who are we? Business Continuity Management (BCM) What is it? Singapore Standard SS540
Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY 14304-1745
ECP - 601: Effective Business Continuity Management: ISO 22301 This 3-day course provides an intensive, hands-on workshop covering all major aspects for the design of an effective Business Continuity Plan
Plan Development Getting from Principles to Paper
Plan Development Getting from Principles to Paper March 22, 2015 Table of Contents / Agenda Goals of the workshop Overview of relevant standards Industry standards Government regulations Company standards
BCP and DR. P K Patel AGM, MoF
BCP and DR P K Patel AGM, MoF Key difference between BS 25999 and ISO 22301 ISO 22301 puts a much greater emphasis on setting the objectives, monitoring performance and metrics aligning BC to top management
CHAPTER 1: BUSINESS CONTINUITY MANAGEMENT STRATEGY AND POLICY
Zurich Management Services Limited Registered in England: No 2741053 Registered Office The Zurich Centre, 3000 Parkway Whiteley, Fareham Hampshire, PO15 7JZ CHAPTER 1: BUSINESS CONTINUITY MANAGEMENT STRATEGY
AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1
AUDITING A BCP PLAN Thomas Bronack Auditing a BCP Plan presentation Page: 1 What are the Objectives of a Good BCP Plan Protect employees Restore critical business processes or functions to minimize the
Coping with a major business disruption. Some practical advice
Coping with a major business disruption Some practical advice Coping with a major business disruption What is business continuity? Business continuity planning (BCP) is a management process that helps
BS 25999 BUSINESS CONTINUITY MANAGEMENT
BS 25999 BUSINESS CONTINUITY MANAGEMENT AUDIT, CERTIFICATION & training services HOW CAN YOU ENSURE BUSINESS CONTINUITY? BS 25999 AUDITS & CERTIFICATION FROM SGS Most organisations will, at some point,
Global Statement of Business Continuity
Business Continuity Management Version 1.0-2014 Date October 18, 2014 Status Author Business Continuity Management (BCM) Page 1 of 8 Table of Contents 1. Credit Suisse Business Continuity Statement 3 2.
Business Continuity Management Review
Office of Internal Audit Business Continuity Management Review November 14, 2014 Internal Audit Team Shannon Henry Chief Audit Officer & Executive Director of Institutional Compliance Stacy Sneed Audit
Business Continuity Planning and Disaster Recovery Planning
4 Business Continuity Planning and Disaster Recovery Planning Basic Concepts 1. Business Continuity Management: Business Continuity means maintaining the uninterrupted availability of all key business
PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA
1 Chapter-4: Business Continuity Planning and Disaster Recovery Planning PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA Learning Objectives 2 To understand the concept of Business Continuity Management To understand
NHS Hardwick Clinical Commissioning Group. Business Continuity Policy
NHS Hardwick Clinical Commissioning Group Business Continuity Policy Version Date: 26 January 2016 Version Number: 2.0 Status: Approved Next Revision Due: January 2017 Gordon Stevens MBCI Corporate Assurance
Sustainability through Business Continuity Management
Sustainability through Business Continuity Management R Vaidhyanathan (RV) MBCI,CBCP, TE BS25999, BS25999LA, BCCE, 27001LA, ITIL Practice Head for Crisis Management & BCM Continuity and Resilience (CORE)
Business Continuity Management
Business Continuity Management Policy Statement & Strategy July 2009 Basildon District Council Business Continuity Management Policy Statement The Council is committed to ensuring robust and effective
Birmingham CrossCity Clinical Commissioning Group. Business Continuity Management Policy
Birmingham CrossCity Clinical Commissioning Group Business Continuity Management Policy Version V1.0 Ratified by Operational Development Group Date ratified 6 th November 2014 Name of originator / author
Business Resilience and Risk Management
Policy Business Resilience and Risk Management Document Number GOV-POL-37 1.0 Policy Statement Stanwell is committed to delivering a business resilience platform across all levels of the business and its
Business Continuity Management Framework
Business Continuity Management Framework Date of Issue: November 2013 Review Date: November 2014 Written by: Jackie Orchard Risk & Business Continuity Manager Authorised by: Signed off by: DCC Francis
Kuala Lumpur, Malaysia, 25 26 May 2010. Report
Cooperative Arrangement for the Prevention of Spread of Communicable Disease through Air travel (CAPSCA) Workshop / Seminar on Aviation Business Continuity Planning Kuala Lumpur, Malaysia, 25 26 May 2010
Emergency Response and Business Continuity Management Policy
Emergency Response and Business Continuity Management Policy Owner: John Duffy, Registrar & Secretary Last updated: September 2012 Version: 04 Document control Date Version Author Changes To be populated
BUSINESS CONTINUITY MANAGEMENT FRAMEWORK
BUSINESS CONTINUITY MANAGEMENT FRAMEWORK Document Author: Civil Contingencies Service - Authorised by the CCS Joint Management Board - Version 1.0. Issued December 2012 Page 1 FRAMEWORK STATEMENT Business
Business Continuity Management
Business Continuity Management Factsheet To prepare for change, change the way you prepare In an intensely competitive environment, a permanent market presence is essential in order to satisfy customers
ISO 22301:2012 Societal Security Appendix B Business Continuity Management Systems Requirements 347
Appendix B Business Continuity Management Systems Requirements 347 B.3 Format and Structure ISO 22301 is the second published standard to adopt ISO s new high-level structure for management systems standards
Moving from BS 25999-2 to ISO 22301. The new international standard for business continuity management systems. Transition Guide
Transition Guide Moving from BS 25999-2 to ISO 22301 The new international standard for business continuity management systems Extract from The Route Map to Business Continuity Management: Meeting the
Overview TECHIS60851. Manage information security business resilience activities
Overview Information security business resilience encompasses business continuity and disaster recovery from information security threats. As well as addressing the consequences of a major security incident,
Business Continuity Management
Business Continuity Management Standard Operating Procedure Notice: This document has been made available through the Police Service of Scotland Freedom of Information Publication Scheme. It should not
BCM and DRP - RFP Template
BCM and DRP - The Supreme Council of Information & Communication Technology ictqatar PUBLICATION DATE Document Reference This document should be used as an example of the contents of an RFP for business
KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity
INFORMATION RISK MANAGEMENT KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity ADVISORY Contents Agenda: Global trends and BCM
BSO Board Director of Human Resources & Corporate Services Business Continuity Policy. 28 February 2012
To: From: Subject: Status: Date of Meeting: BSO Board Director of Human Resources & Corporate Services Business Continuity Policy For Approval 28 February 2012 The Board is asked to agree the attached
Principles for BCM requirements for the Dutch financial sector and its providers.
Principles for BCM requirements for the Dutch financial sector and its providers. Platform Business Continuity Vitale Infrastructuur Financiële sector (BC VIF) Werkgroep BCM requirements 21 September 2011
WEST YORKSHIRE FIRE & RESCUE SERVICE. Business Continuity Management Strategy
WEST YORKSHIRE FIRE & RESCUE SERVICE Business Continuity Management Strategy Date Issued: 12 November 2012 Review Date: 12 November 2015 Version Control Version Number Date Author Comment 0.1 June 2011
Business Continuity and Risk Management. Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited
Business Continuity and Risk Management Ken Kaberia Principal BCM Officer, Enterprise Risk Safaricom Limited What does Business Continuity mean? Business Continuity Management- Definition Business Continuity
Business Continuity and Disaster Recovery Planning
Business Continuity and Disaster Recovery Planning Jennifer Brandt, CISA A p r i l 16, 2015 HISTORY OF STINNETT & ASSOCIATES Stinnett & Associates (Stinnett) is a professional advisory firm offering services
JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc.
JOB ANNOUNCEMENT Chief Security Officer, Cheniere Energy, Inc. Position Overview The Vice President and Chief Security Risk Officer (CSRO) reports to the Chairman, Chief Executive Officer and President
Business Continuity Management Software
Business Continuity Management (BCM) Software 1 Business Continuity Management Software All In One Continuity Management Solution A Single Platform Approach Manage entire lifecycle with comprehensive BC
Business Continuity Planning for Water Utilities: Guidance Document [Project #4319]
Business Continuity Planning for Water Utilities: Guidance Document [Project #4319] ORDER NUMBER: 4319 DATE AVAILABLE: June 2013 PRINCIPAL INVESTIGATORS: Jack Moyer, Rhiannon Kincaid, Kory Wilmot, Kate
RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief
RSA ARCHER BUSINESS CONTINUITY MANAGEMENT AND OPERATIONS Solution Brief INTRODUCTION Now more than ever, organizations depend on services, business processes and technologies to generate revenue and meet
ESCB definitions of major business continuity terms in relation to payment and securities settlement systems 1
ESCB definitions of major business continuity terms in relation to payment and securities settlement systems 1 June 2007 The ESCB has developed a glossary of major business continuity terms for market
The Resilient IT Infrastructure
The Resilient IT Infrastructure Jeremy Wong Senior Vice President BCM Institute Republic Polytechnic, Block W4, Level 1, LR-W4B 25 November 2013 Jeremy Wong Senior Vice President Business Continuity Management
Subject Area 1 Project Initiation and Management
DRII/BCI Professional Practice Narrative: Establish the need for a Business Continuity Plan (BCP), including obtaining management support and organizing and managing the BCP project to completion. (This
CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT
CONTINUITY OF OPERATIONS AUDIT PROGRAM EVALUATION AND AUDIT April 16, 2014 INTRODUCTION Purpose The purpose of the audit is to give assurance that the development of the Metropolitan Council s Continuity
Business Continuity Policy and Business Continuity Management System
Business Continuity Policy and Business Continuity Management System Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain
Business Continuity Standards A Primer
INTELLIGENT NOTIFICATION Alphabet Soup: Making Sense of BC/DR Standards Part 1: Business Continuity Standards A Primer Why all the attention now? One of the hottest topics in BC/DR these days is standards.
Business Continuity Management. Policy Statement and Strategy
Business Continuity Management Policy Statement and Strategy November 2011 Title Business Continuity Management Policy & Strategy Date of Publication: Cabinet Council Published by Borough Council of King
COMCARE BUSINESS CONTINUITY MANAGEMENT
COMCARE BUSINESS CONTINUITY MANAGEMENT Title Business Continuity Management Version 2.1 Authorised by Executive Committee Effective date Authorisation date 10/7/2012 10/7/2012 COMCARE BUSINESS CONTINUITY
Solihull Clinical Commissioning Group
Solihull Clinical Commissioning Group Business Continuity Policy Version v1 Ratified by SMT Date ratified 24 February 2014 Name of originator / author CSU Corporate Services Review date Annual Target audience
With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS
How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning The world has experienced a great deal of natural and man-made upheaval and destruction in the past few years, including tornadoes,
NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00)
NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00) Subject and version number of document: Serial Number: Business Continuity Management Policy
The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)
Information Technology Disaster Recovery Policy Policy Statement This policy defines acceptable methods for disaster recovery planning, preparedness, management and mitigation of IT systems and services
Chapter I: Fundamentals of Business Continuity Management
Chapter I: Fundamentals of Business Continuity Management Objectives Define Business Continuity Management (BCM) Define the relationship between BCM and risk management Review BCM responsibilities Identify
Business Continuity Management
GENERALLY ACCESSIBLE Business Continuity Management Field Report from an Audit Point of View ISACA Swiss Chapter - After Hour Seminar 28 August 2006 - Urs Voigt - Group Internal Audit Disasters Happen
Business Continuity Plan
Business Continuity Plan October 2007 Agenda Business continuity plan definition Evolution of the business continuity plan Business continuity plan life cycle FFIEC & Business continuity plan Questions
Effective risk management
Effective risk management Our holistic and disciplined risk management program is designed to mitigate risks at all levels of our business in order to protect our clients interests. 2 Vanguard > Effective
CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM
A WHITE PAPER CSC AND THE BUSINESS CONTINUITY MATURITY ASSESSMENT PROGRAM AUTHORS: Neil A. Smith, MBCP [email protected] Sandra Riddell, MBCI [email protected] CSC Papers 2013 ABSTRACT The auditors said
Business Continuity Management Governance. Frank Higgins Abu Dhabi March 2015
Business Continuity Management Governance Frank Higgins Abu Dhabi March 2015 Different Names Same Concept BCM (Business Continuity Management) BSI 25999 IPOCM (Incident Preparedness & Operational Continuity
CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT
CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT JANUARY 2008 GUIDELINE ON BUSINESS CONTINUITY GUIDELINE CBK/PG/14
Leveraging the IT Service Continuity Management framework Gord Novoselnik Business Continuity Office Enterprise Solutions Division
Leveraging the IT Service Continuity Management framework Gord Novoselnik Business Continuity Office Enterprise Solutions Division 1 MTS Allstream Inc. proprietary. Use pursuant to company instructions./
Business Continuity Management Program Development Guide
Business Continuity Management Program Development Guide Prepared by The NS Emergency Management Office, Winter 2012 Version 1.1 Page 2 of 24 Document Revision History Date Author Revision Notes Fall 2011
BUSINESS CONTINUITY POLICY
BUSINESS CONTINUITY POLICY Document Type Corporate Policy Unique Identifier CO-038 Document Purpose To provide a structure through which: i. A comprehensive business continuity management system (BCMS)
Business Continuity Management Policy
Business Continuity Management Policy Policy Holder: Authoriser: Caroline Gover, Head of Business Continuity Caroline Thomson, Chief Operating Officer Reviewed on: Feb 08 Reviewed on: Feb 08 Next Review
Business Continuity Policy
Business Continuity Policy Summary: This policy sets out the structure for ensuring that the PCT has effective Business Continuity Plans in place in order to maintain its essential business functions during
A BCP Tale: From Theory to Practice
A BCP Tale: From Theory to Practice Presenter: Gord Novoselnik Problem & Configuration Manager, Enterprise Solutions Division, MTS Allstream [email protected] 1 10 Commandments of BCM I.
BC / DR Implementation Tying Disaster Recovery Investment to Measurable Business Value
BC / DR Implementation Tying Disaster Investment to Measurable Business Value Continuity Insights Conference May 16-18, 2005 Agenda Purpose Discuss best practice process and tools that might be leveraged
Planning for Disaster. Ramesh Ramani CISM CGEIT [email protected] 02 June 2010
Planning for Disaster Ramesh Ramani CISM CGEIT [email protected] 02 June 2010 Agenda Disaster Management-Introduction Examples BCP and IT Continuity Process of Disaster Management-PDCA Disaster Management
ISO 22301: Societal Security Terminology ISO 22313: BCMS Guidance ISO 22398: Exercises and Testing - Guidance
The Impact of ISO 22301 Moving Your BCM Program to a Management System Implementing the Newly Approved International Business Continuity Management System Standard & Guidance Documents ISO 22301: Societal
HB 292 2006 A Practitioners Guide to Business Continuity Management
HB 292 2006 A Practitioners Guide to Business Continuity Management HB HB 292 2006 Handbook A practitioners guide to business continuity management First published as HB 292 2006. COPYRIGHT Standards Australia
Il nuovo standard ISO 22301 sulla Business Continuity Scenari ed opportunità
Il nuovo standard ISO 22301 sulla Business Continuity Scenari ed opportunità Massimo Cacciotti Business Services Manager BSI Group Italia Agenda BSI: Introduction 1. Why we need BCM? 2. Benefits of BCM
CISM ITEM DEVELOPMENT GUIDE
CISM ITEM DEVELOPMENT GUIDE Updated January 2015 TABLE OF CONTENTS Content Page Purpose of the CISM Item Development Guide 3 CISM Exam Structure 3 Writing Quality Items 3 Multiple-Choice Items 4 Steps
NEEDS BASED PLANNING FOR IT DISASTER RECOVERY
The Define/Align/Approve Reference Series NEEDS BASED PLANNING FOR IT DISASTER RECOVERY Disaster recovery planning is essential it s also expensive. That s why every step taken and dollar spent must be
Business Continuity Planning. A guide to loss prevention
Business Continuity Planning A guide to loss prevention There are many statistics quoted about the effect that a lack of planning for a disaster has on a business. What s certain is that any unplanned
Business Continuity Policy
Business Continuity Policy St Mary Magdalene Academy V1.0 / September 2014 Document Control Document Details Document Title Document Type Business Continuity Policy Policy Version 2.0 Effective From 1st
Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT
INFORMATION SECURITY: UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT FACTSHEET This factsheet will introduce you to Business Continuity Management (BCM), which is a process developed to counteract systems
Update from the Business Continuity Working Group
23 June 2014 Performance and Resources Board 19 To note Update from the Business Continuity Working Group Issue 1 The Business Continuity Working Group oversees the development, maintenance and improvement
PBSi Business Continuity Planning
Business Continuity Planning Definition Business Continuity planning is a planning process designed to reduce the risk that disruptive failures or events could seriously harm your business. It is designed
NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY
NHS ISLE OF WIGHT CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY POLICY AUTHOR/ APPROVAL DETAILS Document Author Written By: Human Resources Authorised Signature Authorised By: Helen Shields Date: 20
